QMSAdvisor

Quality Systems

ISO 13485: Quality Management Systems for Medical Devices

ISO 13485 is the quality management system standard written for the medical device sector. Since FDA's Quality Management System Regulation took effect on February 2, 2026, ISO 13485:2016 is incorporated by reference into 21 CFR Part 820, so the same requirements now sit behind certification audits, MDSAP audits and FDA inspections.

At a Glance

Standard
ISO 13485
Subject
Quality Management Systems for Medical Devices
Group
Quality Systems
Industries
16 industry guides reference it

A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.

What It Covers

ISO 13485 sets out what a quality management system must do when its purpose is meeting regulatory requirements for medical devices. It spans the whole life cycle: management responsibility, resources and competence, infrastructure and work environment, design and development, purchasing, production and service provision, monitoring and measurement, nonconforming product, and corrective and preventive action. A risk-based approach runs through it, and it expects documented procedures and records wherever device safety and performance depend on them.

Unlike a general business QMS, it is built around regulatory obligations. The organization identifies its role (manufacturer, contract manufacturer, supplier, distributor and so on) and the regulatory requirements that apply to it, and justifies any requirement it doesn't apply. The emphasis is on maintaining an effective system, with specific expectations for process validation, sterile and implantable product, traceability, complaint handling and reporting to regulatory authorities.

In practice it is the backbone of most device quality systems. FDA's QMSR incorporates ISO 13485:2016 by reference and adds FDA-specific requirements, for example on records such as complaint and servicing records and UDI, and on labeling and packaging controls. Certification by a certification body is a separate, voluntary step that many markets and customers expect, and MDSAP audits are built on the same standard.

Who It Applies To

  • Medical device manufacturers selling in the US under the QMSR
  • Firms seeking ISO 13485 certification for market access or customer requirements
  • Contract manufacturers, sterilizers and critical suppliers to device makers
  • Companies preparing for MDSAP or EU notified body audits
  • Startups building a first QMS ahead of design transfer or a submission

What Auditors Check

  • Scope and Applicability

    A defined QMS scope, the organization's regulatory role, and a documented justification for any requirement not applied, especially a design and development exclusion.

  • Management Review and Oversight

    Management review records with real inputs, decisions and actions, and evidence that quality objectives and resources are managed. Under the QMSR these records are open to FDA inspection.

  • Design and Development Records

    Design plans, inputs, outputs, verification, validation, transfer and change records that trace to one another, with design reviews that show actual decisions.

  • Purchasing and Supplier Controls

    Supplier evaluation criteria tied to risk, an approved supplier list, clear purchasing data and ongoing monitoring of supplier performance.

  • Production and Process Validation

    Validated processes where output can't be fully verified, controlled work instructions, production records, and identification and traceability.

  • CAPA and Complaint Handling

    Complaints evaluated for reportability, nonconformities and trends feeding CAPA, and root cause investigations closed with effectiveness checks.

  • Internal Audits

    A planned internal audit program covering the whole QMS, auditors independent of the work audited, and follow-up of every finding.

Related Services

Questions

Does the QMSR mean FDA issues ISO 13485 certificates?

No. FDA inspects against the QMSR, which incorporates ISO 13485:2016 by reference and adds FDA-specific requirements, but FDA doesn't issue certificates. Certification comes from a certification body through its own audit cycle, and holding a certificate doesn't exempt a firm from FDA inspection.

We already hold an ISO 13485 certificate. Are we ready for the QMSR?

You're likely closer than a firm still built around the old Quality System regulation, but not automatically ready. The QMSR adds FDA-specific requirements, such as certain records and labeling and packaging controls, and FDA investigators bring their own inspection approach. A gap assessment against both the standard and the FDA additions shows what's left.

Can we exclude design and development?

ISO 13485 lets an organization exclude requirements that genuinely don't apply, such as design and development when it doesn't design devices, but the exclusion has to be justified in the QMS documentation. Whether it holds up depends on your role and your device. Outsourcing design work doesn't remove the design owner's responsibility for it. In the US, the QMSR doesn't allow the exclusion for class II and class III devices or for the class I devices listed in 21 CFR 820.10(c).

What does an ISO 13485 certification cycle look like?

A certification body runs a Stage 1 audit of documentation and readiness, then a Stage 2 audit of implementation. Certificates run on a three-year cycle, with surveillance audits at least annually and a recertification audit before the certificate expires.

ISO 13485

Check Your Quality System Against ISO 13485

An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.